Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: Storm-0978, Tropical Scorpius, UNC2596, APT34, Smoke Sandstorm, Imperial Kitten, Earth Preta, Stately Taurus, APT28, UNC1549, Yellow Liderc, CASCADE PANDA, YoroTrooper, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, TA446, GOSSAMER BEAR, TAG-53, IRON FRONTIER, UNC4057, COLD RELIC, Desert Falcon, Arid Viper, Bearded Barbie, Two-tailed Scorpion, Nascent Ursa, Nodaria, FROZENVISTA, Storm-0587, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, Ruinous Ursa, NIOBIUM, RENEGADE JACKAL, Desert Falcons, Scimitar

Description

TA455—also known by aliases such as Storm‑0978, APT28, and Imperial Kitten—has been linked to a persistent, multi‐campaign espionage effort that targets aerospace, defense, finance, and many other sectors across the globe. In its latest “Iranian Dream Job” operation, the group leveraged LinkedIn spear phishing links that entice victims with enticing job opportunities, delivering malicious ZIP files that contain an obfuscated executable (secur32.dll). The payload exploits a WinRAR zero‑day (CVE‑2025‑8088) to silently extract and deploy a multi‑stage backdoor portfolio including SnapBot variants, RustyClaw, Mythic agents, MiniJunk, MiniBrowse, and other custom malware. TA455’s operations also demonstrate extensive defense‑evasion techniques. The group uses DLL hijacking, NTFS alternate data streams to hide code, and malicious JavaScript that exploits CVE‑2018‑6065 in Chrome to redirect victims through Cloudflare‐like domains before downloading encrypted binaries from command‑and‑control servers. In addition, they deploy PowerShell loaders with heavily obfuscated shellcode and use hardened Cobalt Strike beacons that employ custom malleable profiles. A notable aspect of TA455’s strategy is the intentional mimicry of North Korean Lazarus group TTPs, which introduces attribution ambiguity and slows investigative response. The group also extends its reach through multi‑stage infection chains—such as weaponized DOCX files exploiting CVE‑2017‑0199/CVE‑2017‑11882 and LNK/HTA loader archives—to achieve persistence across varied environments.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Manufacturing
Aerospace
Education
Healthcare
Energy
Transportation
Non profit
Critical infrastructure
Aviation
Media
Think tank
Retail
Pharmaceutical
Hospitality
Maritime
Information technology
Chemical
Legal services
Entertainment
Construction
Food agriculture
Utilities
Mining
Oil gas
Nuclear
Gaming

Targeted Countries / Regions

US
RU
CN
UA
IR
AE
IL
BY
VN
PK
IN
TW
JP
KR
PL
TR
KZ
SA
GB
DE
AU
LB
SG
CA
FR
BR
IT
MX
IQ
ES
EG
RO
NG
KP
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 4 hours ago

Executive Summary

TA455 is an Iranian state-sponsored APT that conducts sophisticated espionage campaigns against aerospace, defense and a wide range of critical sectors worldwide. Using deceptive job‑offer lures, spear phishing, zero‑day vulnerabilities and tailored backdoors, the group routinely mimics tactics of rival actors to mislead attribution efforts.

Goals & Targeting

TA455’s overarching mission is espionage, focused on acquiring privileged information from adversary governments, defense contractors and critical infrastructure operators. By disguising its operations as those of well‑known criminal or state actors and exploiting high‑value sectors like aerospace and telecommunications, the group seeks to infiltrate both technical systems and human resources, leveraging deceptive recruitment tactics to gain insider footholds.

Enhanced Description

Key Capabilities

  • Spear phishing via LinkedIn job offers
  • Zero‑day exploitation of WinRAR CVE-2025-8088 for silent archive extraction
  • Delivery of backdoors including SnipBot variant, RustyClaw, Mythic agent, MiniJunk and MiniBrowse stealer
  • Credential theft from Chrome/Edge browsers using MiniBrowse
  • Persistence via firmware implants and custom SNMP tooling
  • DLL hijacking into legitimate executables
  • Use of NTFS Alternate Data Streams to hide malicious files
  • Spear phishing with impersonated software updates or internal documents
  • Web‑based redirect chains using malicious JavaScript (CVE-2018-6065 in Chrome)
  • Hardcoded 64‑bit shellcode that contacts C2 and downloads encrypted binaries
  • In‑memory obfuscated PowerShell loaders executing shellcode
  • Use of malicious archives containing LNK/HTA loaders for initial infection
  • Weaponized DOCX exploiting CVE-2017-0199/CVE-2017-11882
  • Customized Cobalt Strike malleable profile to evade detection

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Defense Evasion
Command and Control

ATT&CK Techniques

T1566.002
T1204
T1068
T1193
T1203
T1059.001
T1027

Software / Tooling

SnailResin
SnipBot Variant
RustyClaw
Mythic Agent
MiniJunk
MiniBrowse
Cobalt Strike
HTA/LNK Loader
InvisiMole
SocGholish
Akira
Zebrocy
ShadowPad
Turla
Winnti
OilRig
GoRed
Kimsuky
MINIBIKE
Naikon
PipeMagic
Polyglot
Void
XDSpy

Campaigns & Victims

TA455’s campaigns are executed at a brisk pace, utilizing multiple infection vectors across more than 30 target countries. The group systematically builds multi‑stage pipelines that begin with spear‑phishing lures (job offers or software updates), advance through zero‑day exploits and malicious archive delivery, and culminate in persistent backdoor installation. Operations such as the Dream Job Campaign, Operation FrostBeacon targeting Russian B2B firms, and SHADOW‑VOID‑042 showcase a pattern of exploiting public or private sector weaknesses and leveraging decoy websites that mimic legitimate services. These campaigns demonstrate a clear strategic intent: to obtain classified information from high‑value industrial and governmental targets while masking their footprints by replicating the TTPs of rival threat actors. Operational tempo is characterized by rapid iteration—new spear-phishing templates, updated payloads, and continuous changes in command‑and‑control domains. Victims span defense contractors, aerospace manufacturers, financial institutions, telecommunications operators, and non‑profits, with a significant focus on European, Asian, and North American entities. Notable past operations include the Iranian Dream Job Campaign (LinkedIn spear phishing delivering WinRAR zero-day payloads), and Operation FrostBeacon which leveraged weaponized DOCX files to infect Russian B2B firms. The group’s consistent use of multi‑layered infection stages suggests a focus on resilience against detection across diverse environments.

IOC Patterns

  • WinRAR path‐traversal exploit CVE‑2025‑8088
  • NTFS Alternate Data Streams used for file hiding
  • Malicious archives containing LNK/HTA loaders
  • Weaponized DOCX exploiting CVE‑2017‑0199/CVE‑2017‑11882
  • JavaScript exploitation of Chrome vulnerability CVE‑2018‑6065
  • Hardcoded 64‑bit shellcode embedded in JavaScript files
  • Encrypted binary payload download via C2 requests
  • Malware signed with SSL.com certificates
  • Redirection chains mimicking Cloudflare authentication flows

Recommended Actions

  • Apply the latest WinRAR patch (July 30, 2025) or disable automatic extraction of untrusted archives.
  • Enforce anti‑phishing rules on LinkedIn spear‑phishing campaigns; enable mail gateway protection for malicious attachment types.
  • Monitor and block DLL hijacking and legitimate executable tampering observed in Windows environments.
  • Harden browsers to prevent credential theft (e.g., deploy controlled browser profiles or extensions blocking Chrome/Edge stealer).
  • Patch Chrome to mitigate CVE‑2018‑6065; filter JavaScript exploitation attempts from malicious sites.
  • Block malicious archives containing LNK/HTA loaders and weaponized DOCX files.
  • Deploy EDR solutions that detect obfuscated PowerShell execution and in‑memory loader activity.
  • Use web filtering or DNS blacklisting to block decoy domains including Cloudflare mimics and known TA455 command‑and‑control hosts.
  • Maintain updated signing certificate trust stores to detect malware signed with untrusted certificates such as SSL.com.
  • Conduct regular security awareness training emphasizing job offer fraud and social engineering.

Suggested Tags

TA455
Dream Job Campaign
Financial Sector Threat
Manufacturing Sector Threat
Defense Sector Threat
Logistics Sector Threat
Aviation Sector Threat
Telecommunications Sector Threat
Spearphishing via LinkedIn
Zero‑Day Vulnerability Exploit
Backdoor Deployment
Credential Theft from Browsers
DLL Hijacking
Social Engineering
Web Exploit
CVE‑2018‑6065
PowerShell Obfuscation
Cobalt Strike
Russian B2B Targeting
Decoy Websites

Confidence Assessment

The information consolidates multiple open‑source reports and technical analyses, yielding a moderate confidence assessment. Evidence for core capabilities (spear phishing, zero‑day exploitation, backdoor deployment) is well‑documented, but attribution claims are complicated by the group’s deliberate mimicry of rival actors such as Lazarus and overlapping tool families with other Iranian state sponsors. Key gaps remain in the precise timeline of activity, comprehensive IOC coverage across all campaigns, and internal evidence confirming every listed TTP. Continuous monitoring and cross‑validation against additional threat intelligence feeds are recommended to refine this assessment.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 5 Filename 7 Domain 5 IPv4 Address 2 Email Address 1

References

  1. www.eset.com — Cited by web research for: Storm-0978
  2. attack.mitre.org — Cited by web research for: Payload
  3. apt.etda.or.th — Cited by web research for: Cobalt
  4. ics-cert.kaspersky.com — Cited by web research for: PipeMagic
  5. ics-cert.kaspersky.com — Cited by web research for: GoRed
  6. www.proofpoint.com — Cited by web research for: cmd.exe
  7. https://www.clearskysec.com/irdreamjob24/ — Cited by AI analysis.
  8. https://www.proofpoint.com/us/blog/threat-insight/crossed-wires-case-study-iranian-espionage-and-attribution — Cited by AI analysis.

Intel Summary

7

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Iranian Threat Groups
Aerospace Sector
Cyber Espionage
TA455
Dream Job Campaign
Financial Sector Threat
Manufacturing Sector Threat
Defense Sector Threat
Logistics Sector Threat
Aviation Sector Threat
Telecommunications Sector Threat
Spearphishing via LinkedIn
Zero‑Day Vulnerability Exploit
Backdoor Deployment
Credential Theft from Browsers
DLL Hijacking
Social Engineering
Web Exploit
CVE‑2018‑6065
PowerShell Obfuscation
Cobalt Strike
Russian B2B Targeting
Decoy Websites

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
I
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.